Evaluation Framework
Security vendor evaluation should proceed in four phases:
- Requirements definition: Document specific security requirements, integration needs, and success criteria before engaging vendors
- Market survey: Identify qualified vendors through analyst reports (Gartner Magic Quadrant, Forrester Wave), peer recommendations, and RFI responses
- Technical evaluation: Proof of concept testing in your environment against defined success criteria
- Commercial evaluation: Total cost of ownership, contract terms, support quality, and vendor stability
Evaluation Criteria
- Technical capability: Does the solution address your specific requirements?
- Integration: Does it integrate with your existing security stack?
- Operational overhead: How much staff time is required to operate it effectively?
- False positive rate: High false positive rates create alert fatigue and reduce effectiveness
- Support quality: How responsive is the vendor during incidents?
- Roadmap: Is the vendor investing in the capabilities you will need in 3–5 years?
Next-Generation Firewalls
Leading NGFW vendors: Palo Alto Networks, Fortinet, Check Point, Cisco. Key evaluation criteria:
- Throughput at full inspection (SSL decryption significantly reduces throughput — test with SSL enabled)
- Application identification accuracy
- Threat prevention effectiveness (independent test results from NSS Labs, SE Labs)
- Management platform usability and automation capabilities
- Integration with SIEM and SOAR platforms
- High availability and failover capabilities
Test throughput with SSL inspection enabled — many vendors advertise throughput without SSL inspection, which is not representative of real-world performance.
EDR/XDR
Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) provide threat detection and response capabilities at the endpoint and across the security stack. Leading vendors: CrowdStrike, Microsoft Defender, SentinelOne, Palo Alto Cortex XDR.
EDR vs. XDR
- EDR: Focused on endpoint telemetry — process execution, file activity, network connections, registry changes
- XDR: Extends EDR with telemetry from network, cloud, identity, and email — provides broader visibility and correlated detection
Evaluation Criteria
- Detection rate for known and unknown threats (MITRE ATT&CK evaluation results)
- False positive rate — high false positives create alert fatigue
- Response capabilities — can the platform automatically contain threats?
- Performance impact on endpoints
- Coverage for your OS mix (Windows, Linux, macOS)
SIEM & SOAR
Security Information and Event Management (SIEM) collects and analyzes security events from across the environment. Security Orchestration, Automation, and Response (SOAR) automates incident response workflows. Leading vendors: Microsoft Sentinel, Splunk, IBM QRadar, Elastic Security.
SIEM Evaluation Criteria
- Ingestion capacity and cost model (per-GB pricing can be expensive at scale)
- Detection rule quality and out-of-box content
- Query performance for threat hunting
- Integration with your existing security tools
- Cloud-native vs. on-premises deployment options
SOAR Considerations
SOAR platforms require significant investment to configure and maintain playbooks. Evaluate: pre-built playbook library, integration ecosystem, and the vendor's professional services capability for initial deployment.
MSSP & MDR Services
Managed Security Service Providers (MSSP) and Managed Detection and Response (MDR) providers offer 24/7 security monitoring and response. Key differences:
- MSSP: Manages security tools and provides monitoring. Broader scope; variable quality.
- MDR: Focused on threat detection and response. Uses proprietary technology and threat intelligence. Higher quality detection; narrower scope.
Evaluation Criteria
- Mean time to detect (MTTD) and mean time to respond (MTTR) — ask for actual metrics, not marketing claims
- Analyst quality — what are the qualifications and experience of the analysts monitoring your environment?
- Escalation procedures — how are critical incidents escalated and how quickly?
- Reference customers — speak with customers who have experienced actual incidents
- Technology stack — what tools does the provider use and how do they integrate with your environment?
Zero Trust Solutions
Zero trust is not a single product — it requires solutions across multiple categories:
- Identity: Azure AD, Okta, Ping Identity for identity federation and conditional access
- Network: Illumio, Guardicore for microsegmentation; Zscaler, Palo Alto Prisma for SASE
- Workload: Aqua Security, Prisma Cloud for container and workload security
- Data: Microsoft Purview, Varonis for data classification and DLP
- PAM: CyberArk, BeyondTrust for privileged access management
Evaluate zero trust solutions as a portfolio, not individual products. Vendor consolidation (using a single vendor's zero trust platform) reduces integration complexity but creates vendor dependency.
Common Procurement Mistakes
- Buying based on analyst rankings alone: Gartner Magic Quadrant leaders are not always the best fit for your specific requirements
- Skipping the PoC: Security products that work well in demos often underperform in actual environments
- Underestimating operational overhead: Many security products require significant staff time to operate effectively
- Ignoring integration costs: Integrating a new security tool with your existing stack often costs as much as the tool itself
- Not testing false positive rates: High false positive rates make security tools counterproductive
- Selecting on price alone: The cheapest security solution is rarely the best value when total cost of ownership and effectiveness are considered